Improper Initialization in Linux kernel - CVE-2026-64327
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper initialization in the f_fs functionfs endpoint file handling when processing early userspace ioctls before USB host connection. A local user can invoke FUNCTIONFS_DMABUF_ATTACH on an endpoint file before the host connects to cause a denial of service.
The issue occurs because endpoint direction checks can use an incorrect DMA direction before the endpoint files are fully initialized for connection state.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64327
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13